Network Working Group S. Santesson Request for Comments: 4262 Microsoft Category: Standards Track December 2005X.509 Certificate Extension for Secure/Multipurpose Internet Mail Extensions (S/MIME) Capabilities
1. Introduction
This document defines a certificate extension for inclusion of S/MIME Capabilities in X.509 public key certificates, as defined by RFC 3280 [RFC3280].
Santesson Standards Track [Page 1]
RFC 4262 S/MIME Capabilities Extensions December 2005
The solution defined in this specification leverages the fact that S/MIME encryption requires possession of the recipient's public key certificate. This certificate already contains information about the recipient's public key and the cryptographic capabilities of this key. Through the extension mechanism defined in this specification, the certificate may also identify the subject's cryptographic S/MIME capabilities. This may then be used as an optional information resource to select appropriate encryption settings for the communication.
1.1. Terminology
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 [STDWORDS].
2. S/MIME Capabilities Extension
This section defines the S/MIME Capabilities extension.
Santesson Standards Track [Page 2]
RFC 4262 S/MIME Capabilities Extensions December 2005
There are numerous different types of S/MIME Capabilities that have been defined in various documents. While all of the different capabilities can be placed in this extension, the intended purpose of this specification is mainly to support inclusion of S/MIME Capabilities specifying content encryption algorithms.
3. Use in Applications
Applications using the S/MIME Capabilities extension SHOULD NOT use information in the extension if more reliable and relevant authenticated capabilities information is available to the application.
4. Security Considerations
The S/MIME Capabilities extension contains a statement about the subject's capabilities made at the time of certificate issuance. Implementers should therefore take into account any effect caused by the change of these capabilities during the lifetime of the certificate.
Santesson Standards Track [Page 3]
RFC 4262 S/MIME Capabilities Extensions December 2005 5. Normative References[STDWORDS] Bradner, S., "Key words for use in RFCs to Indicate
Santesson Standards Track [Page 4]
RFC 4262 S/MIME Capabilities Extensions December 2005
Full Copyright Statement